37883vdb entry
http://osvdb.org/37883 CVE-2007-2839
GFax 0.7.6 - Temporary Files Local Arbitrary Command Execution
Record summary
CVE-2007-2839 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGFax 0.7.6 - Temporary Files Local Arbitrary Command ExecutionExploitDB exploitby Steve KempNot analyzed1 file
References
825937Third-party advisory
http://secunia.com/advisories/25937 25967Third-party advisory
http://secunia.com/advisories/25967 DSA-1329Vendor advisory
http://www.debian.org/security/2007/dsa-1329 24780vdb entry
http://www.securityfocus.com/bid/24780 1018335vdb entry
http://www.securitytracker.com/id?1018335 gfax-deletecrontab-command-execution(35403)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35403 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-2839